dhi.io/socket-cli
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.176-debian-fips-dev, 1.1.176-debian13-fips-dev, 1.1.176-fips-dev
sha256:9fc5d5dba840ed6bf7f2113f6ebffa30f1623628309460ace0249843e4bd547e
Manifest digest:sha256:57c31d79d064b9f7bcc5f1b9e89bdaeccb5d307c1366ec733046cd321cc5c7dd
Size
84.38 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/socket-cli:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/socket-cli:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/socket-cli@sha256:094b3b8adddcd0a8e25b8eed865ba125f8328a82fb8ff9b8637305a625cde6a3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/socket-cli@sha256:28171f1135bfaf164dc1b081db77ddcc18ef11fe5115913eea6623a0f3cf1474 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/socket-cli@sha256:dfff31ae4fced4f7fadfd51f55eae2a2ae1a4e0f5732d4e0610f68f79e60dd85 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/socket-cli@sha256:16532b457df90ba3f0a3872d01c7cb005aeb88509c06ea7f81189a293e00a899 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/socket-cli@sha256:ef50cb9c2fc8b6091b389e2a5f35a432ccd3a5e59617c96f8889ac45fb58142f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/socket-cli@sha256:264c81fa172907927e3bd0e7188cc667d2e4b50aa0ca0c8fc38483963772f3f1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/socket-cli@sha256:53a78602dbc0d86a5bcaaab24be3c8b3f57057ba9c12bd718149926ad646e738 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/socket-cli@sha256:d8aa041e08534e9f7cffb6d5560dc7bdffc2da8ad450610be99b20aa037fcfe3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/socket-cli@sha256:dbd9ce0147fb16df98f6a6c266dc2ea183df9fa24d9d0e2d0af4ea3ab8f647f2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/socket-cli@sha256:1455e82b55b853ab26af4c41bb1dcab97111cc46f42e2434e9c59af9c546c934 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/socket-cli@sha256:3af1ab0d903b56f8437ad80ab1ef3c54283afa983b12261144803ad3669047e5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/socket-cli@sha256:a93be66b1188b8f1dc947f46a55fda73d27d88ca1b6687e0c78eebb7932b095f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/socket-cli@sha256:eb8be399e07be5db038b46f0ba509f1cafecc8d115324e9a5d9dd04613c0e5a4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/socket-cli@sha256:d78d874987535fe3ea3fd4c367c295b4f678065b0f855b9121e3bd6e49cbbed9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/socket-cli@sha256:997d1e0abefa645ff8d9e497602e4c5d3f54b88aaf1b02491ccea202d89cb02a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/socket-cli@sha256:1097d8b296d05837e4c7c50b709e410b6e02f6727aec373e33c52f03ff04c47e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/socket-cli@sha256:0a2f5f03a187593077bb2c3799420a4add4d872af64a36bbf8aecfb25638cede |